commit 4f3882177240a1f55e45a3d241d3121341bead78 upstream.
We should not be leaving half-mapped usages with potentially invalid
keycodes, as that may confuse hidinput_find_key() when the key is located
by index, which may end up feeding way too large keycode into the VT
keyboard handler and cause OOB write there:
BUG: KASAN: global-out-of-bounds in clear_bit include/asm-generic/bitops-instrumented.h:56 [inline]
BUG: KASAN: global-out-of-bounds in kbd_keycode drivers/tty/vt/keyboard.c:1411 [inline]
BUG: KASAN: global-out-of-bounds in kbd_event+0xe6b/0x3790 drivers/tty/vt/keyboard.c:1495
Write of size 8 at addr ffffffff89a1b2d8 by task syz-executor108/1722
...
kbd_keycode drivers/tty/vt/keyboard.c:1411 [inline]
kbd_event+0xe6b/0x3790 drivers/tty/vt/keyboard.c:1495
input_to_handler+0x3b6/0x4c0 drivers/input/input.c:118
input_pass_values.part.0+0x2e3/0x720 drivers/input/input.c:145
input_pass_values drivers/input/input.c:949 [inline]
input_set_keycode+0x290/0x320 drivers/input/input.c:954
evdev_handle_set_keycode_v2+0xc4/0x120 drivers/input/evdev.c:882
evdev_do_ioctl drivers/input/evdev.c:1150 [inline]
Cc: stable@vger.kernel.org
Reported-by: syzbot+19340dff067c2d3835c0@syzkaller.appspotmail.com
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Tested-by: Benjamin Tissoires <benjamin.tissoires@redhat.com>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: Lee Jones <lee.jones@linaro.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Issue: SEC-2698
Change-Id: I66061961e371a502708c3cdcc2da39a20f82b590
(cherry picked from commit 817009b44712dbbb4f6c54af578d7d91bfa6ff82)
commit 52c479697c9b73f628140dcdfcd39ea302d05482 upstream.
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Issue: SEC-2677
[backport to FP2: Missing change "epoll: do not take global 'epmutex'
for simple topologies", so we don't have the full_check condition yet.]
Change-Id: I97468c95d3c22cc5f538dfcf78907aefa35a6503
(cherry picked from commit 1d90193cda629e352eecfe0d1a2cec388c73ab68)
Signed-off-bs: Al Viro <viro@zeniv.linux.org.uk>
Issue: SEC-2677
[Backport: move up declaration of fget_raw_light to before it's used.]
Change-Id: I52cd7555021d13f9c73481ea9a4f2562190524ec
(cherry picked from commit a5b470ba06aa3f96999ede5feba178df6bdb134a)
commit ed9be64eefe26d7d8b0b5b9fa3ffdf425d87a01f upstream.
The HID subsystem allows an "HID report field" to have a different
number of "values" and "usages" when it is allocated. When a field
struct is created, the size of the usage array is guaranteed to be at
least as large as the values array, but it may be larger. This leads to
a potential out-of-bounds write in
__hidinput_change_resolution_multipliers() and an out-of-bounds read in
hidinput_count_leds().
To fix this, let's make sure that both the usage and value arrays are
the same size.
Cc: stable@vger.kernel.org
Signed-off-by: Will McVicker <willmcvicker@google.com>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Lee Jones <lee.jones@linaro.org>
Change-Id: I2dde02fea5a221d77bed8477d3d69f56749a1899
Issue: SEC-2935
(cherry picked from commit fcd3e187c1a2558a1081d819e12d52ed55cf15b7)
Adding fix to check upper limit on the length
of the destination array while copying elements from
source address to avoid stack out of bound error.
Change-Id: Ieb24e8f9b4a2b53fbc9442b25d790b12f737d471
Signed-off-by: Tanwee Kausar <tkausar@codeaurora.org>
Issue: SEC-2931
(cherry picked from commit 4e921964bd0686950cd89eca69e77a5f3f109d3a)
Added a check to validate map before freeing it to avoid Use after
free scenario.
Change-Id: I484391ff7c55c0689530a928a2821ee5a1a0e10c
Signed-off-by: Vamsi krishna Gattupalli <vgattupa@codeaurora.org>
Issue: SEC-2916
(cherry picked from commit 14d4bb80a2adba18b0c4d125dd330fec9f9d4162)
This is needed to get color primaries, transfer and matrix values from
avc devoder.
Issue: FP2P-432
Issue: FP2P-435
Change-Id: Id1d375c9f6e1c05fc9b8336162bb11cc12d6dea2
A sock_tag_entry can only be part of one process's
pqd_entry->sock_tag_list. Retagging the socket only updates
sock_tag_entry->tag, and does not add the tag entry to the current
process's pqd_entry list, nor update sock_tag_entry->pid.
So the sock_tag_entry is only ever present in the
pqd_entry list of the process that initially tagged the socket.
A sock_tag_entry can also get created and not be added to any process's
pqd_entry list. This happens if the process that initially tags the
socket has not opened /dev/xt_qtaguid.
ctrl_cmd_untag() supports untagging from a context other than the
process that initially tagged the socket. Currently, the sock_tag_entry is
only removed from its containing pqd_entry->sock_tag_list if the
process that does the untagging has opened /dev/xt_qtaguid. However, the
tag entry should always be deleted from its pqd entry list (if present).
Issue: SEC-2842
Bug: 176919394
Signed-off-by: Kalesh Singh <kaleshsingh@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I5b6f0c36c0ebefd98cc6873a4057104c7d885ccc
(cherry picked from commit 8f9138d6c464a60f37f1b293bc61ccbcce6210f6)
To prevent protential risk of memory leak caused by closing socket with
out untag it from qtaguid module, the qtaguid module now do not hold any
socket file reference count. Instead, it will increase the sk_refcnt of
the sk struct to prevent a reuse of the socket pointer. And when a socket
is released. It will delete the tag if the socket is previously tagged so
no more resources is held by xt_qtaguid moudle. A flag is added to the untag
process to prevent possible kernel crash caused by fail to delete
corresponding socket_tag_entry list.
Issue: FP2P-307
Test: run cts -m CtsNativeNetTestCases
Change-Id: I163bb06bdbf6aa63503f1f14ec1dd177a72b9df3
(cherry picked from commit b5428181f94bd0d1ff5d321bd58413bdb61f8df4)
psessionEntry->pSchBeaconFrameBegin is allocated with fix length
SCH_MAX_BEACON_SIZE. Do not copy the value to the buffer exceeding
psessionEntry->pSchBeaconFrameBegin.
Change-Id: I539692c01753b991a963b0416177cf5b474cfdf8
CRs-Fixed: 2579375
Drop AMSDU subframes if AMSDU subframe header's DA
is equal to broadcast address.
Change-Id: I21f2b95b45fb150a857d23ba158a0f9df15d5c46
CRs-Fixed: 2897293
Drop inalid EAPOL packets in SAP mode which are not
destined to self mac address.
Change-Id: I9754dddf580e60bd88ddc6e28355162499a8d125
CRs-Fixed: 2868054
Currently, lim silently drops the association if it fails to
post ASSOC_IND due to some reason(e.g. invalid contents of
assoc request) and the MLM state is stuck in
eLIM_MLM_WT_ASSOC_CNF_STATE. Station context is not cleaned up
till the next association. Gracefully cleanup the association
in such failure cases.
Change-Id: I348a7d3ffc537cf89dc311da7bb9846e27635efe
CRs-Fixed: 2857049
list_empty() can still return false even if list is not initialized.
so, while removing from list use count variable to check whether
the list is empty or not.
Change-Id: I436ec6df3ef41227563d1efdb528e0444f199390
CRs-Fixed: 2679126
Currently in the driver, while typecasting the skb data to local
structure in function ptt_sock_proc_reg_req, there can occur a potential
OOB read. The length of the data to be typecasted is not verified
properly.
Add a sanity check to verify that the data being typecasted is of proper
size.
Change-Id: Ib88477a2817649e092e25e21f948c33160dfa09b
CRs-Fixed: 2559499
Add validation check on frameLength to avoid int overflow in
csr_scan_save_preferred_network_found function.
Change-Id: I6bcdfb757610152bc801d5134e62dd58629d1e81
CRs-Fixed: 2232358
Signed-off-by: Gururaj Patil <gururaj.patil3@harman.com>
Currently in the function limProcessActionFrameNoSession, mem_cmp
is done on the received frame pointer without validating the frame_len
which could lead to out-of-bounds memory access if the frame_len is
not matching the size of action_hdr.
Add check to validate the frame_len with action_hdr size before doing
mem_cmp for the p2p oui.
Change-Id: I39329d1a9ef45614d3c617db11a7a7f5ec2aaaec
CRs-Fixed: 2110756
(cherry picked from commit bc13a475626dbbc7d3bac85f1b020d4ac1724cb6)
Propagation to pronoto from cld2.0.
In limProcessActionFrame and limProcessActionFrameNoSession,
The Rx frame pointer is directly casted to the action frame header
to find the Action frame category and action ID without validating
the minimum length of the frame. If the frame len is less than the
action frame header len, then OOB read would occur.
Check if frame_len is less than the size of action frame header len
and return if true.
Change-Id: Idf8ca7eeacdf57171d2850fe6317784911830aac
CRs-Fixed: 2598901
(cherry picked from commit 382cabdaa5b3d7423600679248e771d285643aae)
PE generated disassoc request is not serialized in SME queue. This
results in corrupting 'lim.limDisassocDeauthCnfReq.pMlmDisassocReq'
which is a global context to save disassoc request.
Address the above by indicating all the PE generated disassoc requests
to SME and process disconnection request only after receiving
eWNI_SME_DISASSOC_CNF from SME(similar to that of processing disassoc
request from peer).
Change-Id: I2b93925ba64c4d9ff22b071dd2e5c7681be59e15
CRs-Fixed: 934183
(cherry picked from commit 03cf7ff1db9f7ec73b1b0dff42d05e943113f64f)
[FP2: re-apply https://github.com/LineageOS/android_kernel_huawei_msm8916/commit/71b1c1ed51d3d9b79773e7027ff8fb8e0e406e9d]
In the API, the driver inserts 0 after the SSID name, to mark the
end of the ssid, but if the SSID name is 32 characters which is
the max SSID length possible, the driver puts 0 at the 33rd
place of memory which is not the part of the SSID name, which
results in OOB write, or off-by-one write condition.
Fix is to remove the addition of 0 after ssid, as in every
case the driver prints the ssid, taking the ssid length
as the input, and in that case insertion of 0 will not serve
any purpose.
Change-Id: I1d58026ec9f48fe9d00bd2f50783c65899588978
CRs-Fixed: 2598900
(cherry picked from commit ad65dc9f8a5731d4138ba61f2731f0db3b68bc82)
Link layer stats are not supported as required by CTS, so don't report
support for them.
Undefining WLAN_FEATURE_LINK_LAYER_STATS at build level causes various
build errors, because the flag is not checked properly in all cases or
fall-back implementations are missing. Therefore, instead of disabling
the feature, just hide it from the system instead.
Test: run cts -m CtsStatsdHostTestCases -t android.cts.statsd.atom.HostAtomTests#testWifiActivityInfo
Change-Id: I9d053ff8bdee1352645c3b8f75bfb284f4f0ca05
Link layer stats triggers firmware timeout.
02-17 21:28:32.793 390 390 E WifiHAL : wifi_get_link_stats: requestResponse Error:-7
02-17 21:28:32.805 567 1525 E WifiVendorHal: getWifiLinkLayerStats(l.937) failed {.code = ERROR_UNKNOWN, .description = , timed out}
They weren't queried before pie, so deal without them.
Unfortunately I didn't find a way to teach wifi HAL not to query this so
the log still gets spammed with
02-19 11:31:10.316 393 393 E WifiHAL : wifi_get_link_stats: requestResponse Error:-3
02-19 11:31:10.320 568 1615 E WifiVendorHal: getWifiLinkLayerStats(l.937) failed {.code = ERROR_NOT_SUPPORTED, .description = }
every few seconds. But at least it doesn't hang the device anymore.
Change-Id: Ia00d19b7384605c6ee6b7b68d441a4616e9816a6
(cherry picked from commit
LineageOS/android_kernel_cyanogen_msm8974@7b01570045)
When host sends assoc response to supplicant, it
allocates a buffer of fixed size and copies a variable
length of assoc response IEs to this fixed sized buffer.
There is a possibility of OOB write to the allocated buffer
if the assoc response IEs length is greater than the
allocated buffer size.
To avoid above issue validate the assoc response IEs length
with the allocated buffer size before data copy to the buffer.
Change-Id: Ib12385e9ff04e5172ae8b505faf959e426fda439
CRs-Fixed: 2616226
(cherry picked from commit 9bb1a72f6ebdf5d2b1a466aec732aa9c5bc37c4d)
In function rrm_fill_beacon_ies, the total IE length is
calculated as sum of length field of the IE and 2 (element id 1
byte and IE length field 1 byte). The total IE length is defined
of type uint16_t and will overflow if the *(pBcnIes + 1)=0xfe.
Validate the len against total IE length to avoid overflow.
Change-Id: If8f86952ce43c5923906fc6ef18705f1785c5d88
CRs-Fixed: 2617004
(cherry picked from commit 949b1745b9e1ddd8f81960723643cdf10e5f1963)
Currently, for while loop BcnNumIes is checked against 0
which may cause OOB read for len = *(pBcnIes + 1).
Fix is to check BcnNumIes against size of header i.e 2 instead
of 0 to avoid 00B read.
Change-Id: Id167410da790e449d36853d8505142e1b218e9b8
CRs-Fixed: 2635666
(cherry picked from commit 7957db59a545ac43b260401546f4bc72470783df)
When host sends ft assoc response to supplicant, it
allocates a buffer of fixed size and copies a variable
length of assoc response IEs to this fixed sized buffer.
There is a possibility of OOB write to the allocated buffer
if the assoc response IEs length is greater than the
allocated buffer size.
To avoid above issue validate the assoc response IEs length
with the allocated buffer size before data copy to the buffer.
Change-Id: Ife9c2071a8cc4a2918b9f349f4024478f94b2d78
CRs-Fixed: 2616225
(cherry picked from commit c7ea2364eb458e2706b7bae3ed3e70fba7fa56e6)
lim_is_assoc_req_for_drop() uses pHashTable which can be accessed
by peDeleteSession simulataneously. This can lead to crash as
memory for pHashTable can be deleted.
Fix this by protecting usage of pHashTable with a lock.
Change-Id: Iaef7a26d9f3e1ccb76807c9dcf140a6f3de34d8e
CRs-Fixed: 2771345
(cherry picked from commit 0c398c2bd44fd1370eca2b1aa01a80f4675fea13)
*ported from kernel 3.18
With the wiphy::features flag being used up this patch adds a
new field wiphy::ext_features. Considering extensibility this
new field is declared as a byte array. This extensible flag is
exposed to user-space by NL80211_ATTR_EXT_FEATURES.
Cc: Avinash Patil <patila@marvell.com>
Signed-off-by: Gautam (Gautam Kumar) Shukla <gautams@broadcom.com>
Signed-off-by: Arend van Spriel <arend@broadcom.com>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Git-commit: d75bb06b61cb69ee6223d791d3bb230e68623b20
Git-repo: git://git.kernel.org/pub/scm/linux/kernel/git/jberg/mac80211-next.git
CRs-Fixed: 1098230
Change-Id: Ice288928b17340a571c1acca719325fbf1020072
rpm-regulator-ldoa27 is defined in msm8226-regulator already
Signed-off-by: Francescodario Cuzzocrea <bosconovic@gmail.com>
Change-Id: I64b33b9e0d38da45a5989b5fc36ec4c12dc8fc2b
commit 0b0509508beff65c1d50541861bc0d4973487dc5 upstream.
When allocating space in the target buffer for the security context,
make sure the extra_buffers_size doesn't overflow. This can only
happen if the given size is invalid, but an overflow can turn it
into a valid size. Fail the transaction if an overflow is detected.
Bug: 130571081
Change-Id: Ibaec652d2073491cc426a4a24004a848348316bf
Signed-off-by: Todd Kjos <tkjos@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[haggertk: Backport to 3.4. Omitted return_error_{line,param}]
CVE-2019-2181
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
In case the target node requests a security context, the
extra_buffers_size is increased with the size of the security context.
But, that size is not available for use by regular scatter-gather
buffers; make sure the ending of that buffer is marked correctly.
Bug: 136210786
Acked-by: Todd Kjos <tkjos@google.com>
Fixes: ec74136ded79 ("binder: create node flag to request sender's security context")
Signed-off-by: Martijn Coenen <maco@android.com>
Cc: stable@vger.kernel.org # 5.1+
Link: https://lore.kernel.org/r/20190709110923.220736-1-maco@android.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit a56587065094fd96eb4c2b5ad65571daad32156d)
Change-Id: Icb499a8843814532631de6c12d9709e7540967bf
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>